04 February 2009

CURRENT EVENTS: Russian 0-3 in Cyber Attacks


In January of 2009 the world witnessed the third successful cyber attack against a country. The target was the small country of Kyrgyzstan. The country is only about 77,000 square miles in size with a population of just over 5 million. The attackers focused on the three of the four Internet service providers. They launched a distributed denial of service attack traffic and quickly overwhelmed the three and disrupting all Internet communications. The IP traffic was traced back to Russian-based servers primarily known for cyber crime activity. Multiple sources have blamed the cyber attack on the Russian cyber militia and/or the Russian Business Network (RBN). RBN is thought to control the world's largest botnet with between 150 and 180 million nodes. These reports go on to say that Russian Officials hired the technically capable group to do this. It is widely believed that this group also played a substantial role in the Estonia Attack in 2007 and the attack on Georgia in 2008. The mechanism of attack was a fairly large botnet with nodes distributed in countries around the world. (DefenseTech Enemy among Us) One significant difference in the Kyrgyzstan attack is that most of the DDoS traffic was generated in Russia.

INTEL: One source reports that this attack was commercial -- insinuating the civilian organization (attackers) may have been paid to carry this out.

ANALYSIS: The commercial sourcing of the cyber attack is believed to have been done to put the Russian government an arms length away from the hostile act.
More here...

No comments: